PT-2007-1069 · Mit+3 · Mit-Krb5+4

Publicado

2007-09-04

·

Atualizado

2024-06-15

·

CVE-2007-3999

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: MIT Kerberos 5 versions 1.4 through 1.6.2 nfs-utils-lib versions 1.0.6 nfs-utils-lib-devel versions 1.0.6 mit-krb5 versions prior to 1.5.3-r1
Description: The issue is related to a stack-based buffer overflow in the svcauth gss validate function in lib/rpc/svc auth gss.c in the RPCSEC GSS RPC library, which can be exploited remotely. This can lead to a denial of service (daemon crash) and potentially allow the execution of arbitrary code via a long string in an RPC message. The vulnerability can be exploited to disrupt the confidentiality, integrity, and availability of protected information.
Recommendations: For MIT Kerberos 5 versions 1.4 through 1.6.2, update to a version later than 1.6.2. For nfs-utils-lib versions 1.0.6, consider disabling the vulnerable component until a patch is available. For nfs-utils-lib-devel versions 1.0.6, restrict access to the vulnerable module to minimize the risk of exploitation. For mit-krb5 versions prior to 1.5.3-r1, update to version 1.5.3-r1 or later.

Correção

DoS

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-07449
BDU:2015-07450
BDU:2015-09590
CVE-2007-3999
DSA-1367-1
DSA-1368-1
OPENSUSE-SU-2024:10899-1
OPENSUSE-SU-2024:11002-1
RHSA-2007:0858
RHSA-2007:0913
RHSA-2007:0951
RHSA-2007_0858
RHSA-2007_0913
RHSA-2007_0951

Produtos afetados

Mit Kerberos 5
Red Hat
Mit-Krb5
Nfs-Utils-Lib
Nfs-Utils-Lib-Devel